Security restrictions bypass in Network Time Protocol - CVE-2018-7170

 

Security restrictions bypass in Network Time Protocol - CVE-2018-7170

Published: March 1, 2018 / Updated: March 1, 2018


Vulnerability identifier: #VU10801
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7170
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to bypass security restrictions on the target system.

The weakness exists due to insufficient security restrictions. A remote attacker can create multiple crafted ephemeral associations to bypass security restrictions and modify the clock.

Affected software

Network Time Protocol
Amazon Linux AMI
Gentoo Linux
Arch Linux
IBM AIX
FreeBSD
Slackware Linux
Opensuse
Fedora
ntp
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
Flex System FC3171 8Gb SAN Switch
Flex System FC3171 8Gb SAN Pass-thru

How to mitigate CVE-2018-7170

Update to version 4.2.8p11.

ntp - addressed in versions 4.2.8p11-1.fc26, 4.2.8p11-1.fc27, 4.2.8p12-1.fc27, 4.2.8p12-1.fc28
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.45.00
Flex System FC3171 8Gb SAN Switch - update to 9.1.14.02.00
Flex System FC3171 8Gb SAN Pass-thru - update to 9.1.14.02.00

External References

Related Security Bulletins